Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
History

Tue, 24 Feb 2026 16:30:00 +0000

Type Values Removed Values Added
Title Apache Superset Open Redirect Apache Superset Open Redirect

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2021-04-27T09:27:22.000Z

Updated: 2024-08-03T21:33:17.571Z

Reserved: 2021-03-10T00:00:00.000Z

Link: CVE-2021-28125

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-27T10:15:09.693

Modified: 2024-11-21T05:59:07.970

Link: CVE-2021-28125

cve-icon Redhat

No data.